Third-party risk, actually managed.
DPA chain, vendor questionnaires, continuous monitoring, RBI outsourcing register, DPDP processor obligations. Every vendor. Every relationship. One workspace. dcomply scores every vendor across 6 risk dimensions (security, financial, operational, reputational, DPDP-specific, cross-border), drafts a DPDP-compliant DPA from vendor metadata, and reassesses on triggers your team defines (renewal, incident, sub-processor change, downgrade).
If any of this sounds familiar, you're in the right place.
These are the exact sentences we hear on first calls. If two or three of them ring true, dcomply is the workspace you have been trying to build in a spreadsheet.
Your vendor DPAs are in an inbox folder and none of them are versioned.
You cannot answer "who processes our customer data on our behalf" without a two-day exercise.
Your RBI outsourcing register is a spreadsheet.
Vendor risk assessments happen at onboarding and never again.
You have no exit playbook for a critical vendor.
If you're RBI-regulated, the RBI door covers the outsourcing directions specifically.
Here's what sits above the foundation.
Vendor risk sits at the intersection of five different regulatory regimes. dcomply ships modules for each layer.
Your Vendors Are Your Biggest Breach Risk
Under DPDP Act Section 8, Data Fiduciaries remain liable for how their processors handle personal data
Third-Party Breaches
Over 60% of data breaches originate from third-party vendors. Under the DPDP Act, your organization, not the vendor, faces penalties up to ₹250 Crore for their failures
Manual Assessments Take Weeks
Traditional vendor risk assessments involve spreadsheets, email chains, and weeks of back-and-forth. By the time you finish, the vendor's risk profile has already changed
No Contract Tracking
Most organizations lack standardized vendor contracts with DPDP-specific data protection clauses, breach notification requirements, and data processing limitations
Complete Vendor Risk Lifecycle
AI 6-Dimension Risk Assessment
Every vendor is scored across Data Security (encryption, access controls), Compliance (DPDP adherence, certifications), Operational (BCP, SLA performance), Financial (stability, insurance), Reputational (breach history, regulatory actions), and Strategic (vendor lock-in, exit planning) dimensions.
Automated Vendor Onboarding
Add vendor details and let AI handle the rest. The system generates a risk questionnaire, collects responses, scores the vendor, and flags high-risk areas, reducing onboarding time from weeks to hours.
Vendor Self-Onboarding Portal
Send the vendor a link. They fill in the questionnaire, upload SOC 2, ISO or insurance artefacts, and receive an auto-drafted DPA. Once approved, the record syncs to your vendor master via webhook or API. Your team reviews, it does not do data entry.
AI-Generated Contracts
Generate Data Processing Agreements (DPA), NDAs, MSAs, and SLAs with built-in DPDP Act clauses. Contracts include Section 8 processor obligations, breach notification timelines, data principal rights flow-down, and Section 16 cross-border transfer restrictions.
Risk Level Classification
Vendors are automatically classified as Critical, High, Medium, or Low risk based on their composite score. Critical vendors trigger mandatory review workflows and enhanced monitoring requirements.
Re-assessment & Monitoring
Schedule periodic re-assessments based on risk level, quarterly for critical vendors, annually for low-risk. Track score changes over time and get alerts when a vendor's risk profile deteriorates.
Standard Questionnaires (VSAQ, CAIQ, SIG)
Assess vendors on VSAQ, CSA CAIQ or Shared Assessments SIG out of the box, or build your own question set. Map answers to DPDP, ISO 27001 A.5.19 to A.5.23 and RBI outsourcing controls in one pass, no double-entry.
Contract Lifecycle Management
Track contract expiry dates, renewal deadlines, and amendment history. Get alerts 90, 60, and 30 days before contract expiry so you never operate with an expired vendor agreement.
Everything a TPRM programme needs, in one tenant
Tick these against any RFP or auditor checklist.
Included in the Security & Risk pack. No per-vendor pricing.
Vendor Assessment in 4 Steps
From onboarding to contract generation. AI handles the heavy lifting so you can focus on vendor relationships.
Add vendor details
Enter the vendor's name, services, data access level, and processing activities. The AI pre-populates risk factors based on vendor type and industry.
AI runs 6-dimension assessment
Claude AI evaluates the vendor across all six risk dimensions, generating scores and detailed findings for each category with DPDP Act references.
Review risk scores and findings
Review the composite risk score, dimension breakdowns, and specific risk flags. Accept, override, or request deeper analysis on any dimension.
Generate DPDP-compliant contract
With one click, generate a complete vendor contract (DPA, NDA, MSA, or SLA) with all DPDP-required clauses pre-filled based on the assessment results.
Questions procurement and DPOs actually ask.
Spreadsheet, point TPRM tool, or dcomply?
An honest view. Different tools solve different problems.
| Capability | Spreadsheet | Point TPRM tools (e.g. Narad) | dcomply |
|---|---|---|---|
| DPDP Section 8 processor controls | ✗ | Partial | ✓ Native |
| DPA / NDA / MSA / SLA generation | ✗ | ✗ | ✓ Yes |
| VSAQ / CAIQ / SIG questionnaires | ✗ | ✓ Yes | ✓ Yes |
| Vendor self-onboarding link | ✗ | ✓ Yes | ✓ Yes |
| RBI outsourcing register, SEBI CSCRF evidence | ✗ | ✗ | ✓ Yes |
| Consent, RoPA, breach, DSR in same tenant | ✗ | ✗ | ✓ Yes |
| Answering inbound security questionnaires (DDQ / RFP) with AI | ✗ | ✓ Yes | ✓ Yes |
| Hosted Trust Center for your customers | ✗ | ✓ Yes | Trust Badge only |
| Published pricing, self-serve signup | n/a | ✗ | ✓ Yes |
| Legal, CA and academy ecosystem | ✗ | ✗ | ✓ Yes |
Pick a point TPRM tool if your main job is answering customer security questionnaires every week and you sell to US enterprises on SOC 2. Pick dcomply if your main job is proving DPDP, RBI or ISO 27001 vendor governance to Indian regulators and boards, and you want vendor risk to sit next to consent, breach and DSR in one login. Most Indian SMEs need the second first.
Third-party feature notes verified from public websites, August 2026. Not affiliated with any named vendor.
"RBI inspection was one hour."
"We had 340 vendors and no way to tell which handled customer data. Six weeks after switching, we had a tiered register, active DPAs, and a monitoring schedule. RBI inspection was one hour."
Flat price. No per-vendor charge.
Vendor Risk / TPRM lives inside the Security & Risk pack at ₹11,999/month. Also included in the Pro plan (3 packs) and Enterprise (all 6 packs). Annual billing is 15% off.
Security & Risk pack
ISO 27001, TPRM (Vendor Risk), VAPT, phishing tracker, security risk register, connector & SAST scans.
See full pricingPro plan
Pick 3 packs (bundle Security & Risk with Data Privacy, Corporate, Finance, Legal or Sector). 50 users, 1,000 DSRs, branded portal.
Start freePrefer to poke around first? Try the live workspace, no signup needed.
Take Control of Vendor Risk Today
AI-powered vendor assessments and DPDP-compliant contracts in minutes, not weeks